FROM quay.io/fedora/fedora
RUN dnf -y install vsftpd sscg && dnf -y clean all
COPY vsftpd.conf vsftpd-ssl.conf /etc/vsftpd/
RUN useradd -m sitecopy && echo sitecopy:sitecopy | chpasswd
# Fedora's /etc/shadow has mode 0000, so PAM can only read it as root
# with CAP_DAC_OVERRIDE, which some container runtimes (e.g. on Ubuntu
# 24.04 hosts) don't grant.  Let its owner read it.
RUN chmod 0400 /etc/shadow
RUN mkdir /home/sitecopy/site && chown sitecopy:sitecopy /home/sitecopy/site
# For FTP over TLS: a certificate for localhost signed by a CA
# created by sscg, and a configuration requiring TLS using a separate
# range of passive ports.
RUN sscg --hostname localhost --lifetime 3650 \
        --ca-file /etc/vsftpd/ca.pem --ca-key-file /etc/vsftpd/ca-key.pem \
        --cert-file /etc/vsftpd/cert.pem --cert-key-file /etc/vsftpd/key.pem \
        --dhparams-file /tmp/dhparams.pem
RUN sed -e 's/^pasv_min_port=.*/pasv_min_port=21110/' \
        -e 's/^pasv_max_port=.*/pasv_max_port=21119/' \
        /etc/vsftpd/vsftpd.conf > /etc/vsftpd/vsftpd-tls.conf \
    && cat /etc/vsftpd/vsftpd-ssl.conf >> /etc/vsftpd/vsftpd-tls.conf
ENTRYPOINT ["/usr/sbin/vsftpd"]
CMD ["/etc/vsftpd/vsftpd.conf"]
